CVE-2026-85572: Tutor LMS 4.0.0 - < 4.0.8 - Subscriber+ Cross-Course Lesson Comment Disclosure
The Tutor LMS WordPress plugin before 4.0.8 does not check that a user has access to a course before returning its lesson discussion content, allowing any authenticated user, such as a subscriber, to read comments from courses they are not enrolled in, including comments awaiting moderation.
Affected Software
Event History
Frequently Asked Questions
Which users can exploit this issue?
Any authenticated WordPress user can exploit it, including users with only the Subscriber role. The affected user does not need to be enrolled in the course whose lesson discussion content they access.
What information could be exposed?
Lesson discussion comments from courses the user is not authorized to access may be disclosed. This includes comments that are awaiting moderation.
Which plugin versions are affected?
Tutor LMS versions before 4.0.8 are affected. Version 4.0.8 is not identified as affected by the provided information.